Skip to content

Expect publish output to be shared through a file - #678

Merged
Andarist merged 8 commits into
mainfrom
output-env-var
Jul 1, 2026
Merged

Andarist merged 8 commits into
mainfrom
output-env-var

Conversation

@Andarist

@Andarist Andarist commented Jun 25, 2026 •

Copy link
Copy Markdown
Member

fix #553

@changeset-bot

changeset-bot Bot commented Jun 25, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 414d99c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@changesets/action Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Comment thread src/run.ts
@Andarist
Andarist marked this pull request as ready for review June 30, 2026 07:44
@Andarist
Andarist requested a review from emmatown as a code owner July 1, 2026 08:49
@socket-security

socket-security Bot commented Jul 1, 2026 •

Copy link
Copy Markdown

@Andarist
Andarist added this pull request to the merge queue Jul 1, 2026
Merged via the queue into main with commit f71ae04 Jul 1, 2026
7 checks passed
@Andarist
Andarist deleted the output-env-var branch July 1, 2026 09:09
arshad-shah added a commit to arshad-shah/extforge that referenced this pull request Sep 1, 2026
The 1.0.0 and 1.1.0 releases published to npm but created no git tag and
no GitHub release, while the workflow reported success.

changesets/action v1 detects what was published by regex-matching
`changeset publish` stdout for `New tag: <pkg>@<version>`. #77 upgraded
@changesets/cli to v3, whose clack-style output no longer prints that
line, so the action concluded nothing had been published and skipped
both the tag push and the release creation without failing. Tags were
created on the runner and discarded with it — which is why
`git ls-remote --tags` still stops at 0.6.0.

Upstream replaced stdout parsing with a CHANGESETS_OUTPUT file in v2
(changesets/action#678) and v2 now rejects the CLI v2/action v1 mismatch
outright (changesets/action#699).

v2 renamed every input, so this is not a bare SHA bump:
version -> version-script, publish -> publish-script,
commit -> commit-message, title -> pr-title.

Both env vars are dropped. GITHUB_TOKEN is no longer read from the
environment (changesets/action#674); the `github-token` input defaults to
`github.token`, which is what was being passed. NPM_TOKEN is no longer
used to write an .npmrc (changesets/action#695) — publishing already goes
through OIDC trusted publishing, confirmed by the SLSA provenance
attestation on the published 1.1.0 tarball.

v2 pushes commits and tags through the GitHub API rather than the git
CLI, so `persist-credentials: false` stays safe and tags are signed with
GitHub's GPG key.


Claude-Session: https://claude.ai/code/session_01AZSFjNFjuoeXUjuFkA6Cha

Co-authored-by: Arshad shah <[email protected]>
Co-authored-by: Claude Opus 5 (1M context) <[email protected]>
ByronDWall pushed a commit to commercetools/nimbus that referenced this pull request Sep 23, 2026
…1995)

* ci(release): upgrade changesets/action to v2 for @changesets/cli v3

@changesets/cli v3 no longer prints the "New tag: <pkg>@<version>" lines that
changesets/action v1.9.0 scraped to learn which packages were published. The
action therefore saw zero published packages: it pushed no git tags, created no
GitHub releases, and set published=false -- while npm publishing itself
succeeded. 3.6.0 reached npm with no GitHub release history because of this,
and the publish step still reported success.

Two v3 breaking changes combined to produce the failed run:

- Published-package detection moved from stdout parsing to a shared output file
  named by CHANGESETS_OUTPUT (changesets/action#678). Action v1 has no such
  support and reported published=false, which skipped tagging and releases and
  also un-gated the canary step below.
- `changeset version` now exits 1 when there are no unreleased changesets
  (changesets/changesets#1860); v2 exited 0 silently. That turned the
  un-gated canary step into a hard job failure.

Upstream treats these as a matched pair and action v2 validates it, refusing
CLI v2 (changesets/action#699). There is no equivalent check in v1 for CLI v3,
which is why the mismatch degraded silently instead of failing fast.

Changes:

- changesets/action v1.9.0 -> v2.1.2, using v2's renamed kebab-case inputs and
  passing the app token through the `github-token` input, which is now required
  for custom tokens. `commitMode: github-api` is dropped because v2 uses the
  GitHub API by default.
- Guard both canary steps on the presence of changeset files, so an emptied
  .changeset/ is a clean skip rather than exit 1.
- Add a step asserting that the version present on npm has a matching git tag,
  so a silent tagging failure fails the job instead of reporting success.
- Remove scripts/print_release_version.sh and its step. Its output was read
  nowhere in the workflow, its exit code was swallowed by the surrounding
  command substitution, and it ran `changeset version` followed by
  `git reset --hard` inside the release job.

Co-Authored-By: Claude Opus 5 <[email protected]>

* ci(release): trim the comments added with the changesets v2 upgrade

The explanatory blocks restated the commit message and PR description, which
git blame already reaches, and ran six to eight lines in a file whose idiom is
one- to three-line constraint notes. Keep only what is not visible in the code
and would be re-broken if removed: that the action and CLI majors move
together, that the tag check is deliberately independent of the action's own
report, and why the canary steps test for changeset files before versioning.

Co-Authored-By: Claude Opus 5 <[email protected]>

---------

Co-authored-by: Claude Opus 5 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Tags not pushed if it's scoped without @ prefix

3 participants